Vulnerability Disclosure Policy
If you have found a security problem in something we run, we want to hear about it.
How to report
Email info@newvisionsecurity.com with SECURITY in the subject line. Include what you found, where, and the steps to reproduce it. Screenshots and request captures help. Please do not post details publicly before we have had a chance to fix it.
What to expect
| Stage | Target |
|---|---|
| Acknowledgement of your report | 3 business days |
| Initial assessment and severity | 10 business days |
| Status update while work is in progress | Every 15 days |
| Credit, if you want it, once resolved | On fix release |
In scope
- Web properties operated by New Vision Security LLC, including this site and the SignalGround application
- Public application programming interfaces we publish
Out of scope
- Third-party services we consume but do not control, including Microsoft Azure infrastructure and the Azure Marketplace
- Findings from automated scanners with no demonstrated impact
- Denial of service, volumetric testing, and social engineering of our staff or customers
- Reports about missing security headers or configuration weaknesses with no exploitable path
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue legal action against you for your research. Good faith means: stay within scope, do not access or modify data that is not yours, do not degrade service for others, stop as soon as you have proven the issue, and give us reasonable time to fix it before disclosing.
No bounty
We do not currently operate a paid bounty programme. We will credit researchers who want credit, and we will always tell you what happened with your report.